An Automated Memory Image Forensic Scheme for Linux Systems Based on Containerization Technology

Ruihao Chen, Hui Lin, Qingxin Lin, Ju Hui · 2024

With the advancement of anti-forensic techniques and network attack technologies aided by fileless methods, traditional forensics techniques based on non-volatile storage devices are increasingly encountering obstacles. Consequently, the forensic analysis of runtime data within memory has become increasingly important. In response to the challenges faced by devices running Linux systems, which are constrained by the multitude of Linux kernel versions and distributions, making memory forensics a non-trivial task, this research proposes an automated scheme that deploys a simulated environment consistent with the target system's Linux kernel based on containerization technology. The scheme extracts the memory data structure table from the simulated environment to assist analysts in analyzing Linux system memory images. Additionally, this proposal introduces an automated analysis of Linux memory images to enhance the efficiency of analysts' work, allowing them to focus their energies on the collation and analysis of more critical evidence information, thereby improving the overall efficiency of memory forensics analysis.

Read the paper · More papers on PaperTik